Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: Secure the upload?  (Read 2709 times)

0 Members and 1 Guest are viewing this topic.

Mansour

  • Coppermine newbie
  • Offline Offline
  • Posts: 2
Secure the upload?
« on: January 19, 2007, 12:29:48 pm »

Hi

I was used  cpg1.4.9, and my web site was hacked and all DBs was deleted. They used a vulnerability on cpg1.4.9 to upload a php file and take a full control on my DBs.

I would like to know, how can I secure the upload ? can I use "Password Protect Directories" to add addition authentication on upload files on the server ? I have only one user who allowed uploading to the gallery.

Also, how can I disable the upload at all? I just want to open the gallery without uploading any file. Is deleting the upload.php enough ?


Thanks
Logged

Nibbler

  • Guest
Re: Secure the upload?
« Reply #1 on: January 19, 2007, 12:52:58 pm »

To disable uploading just set permissions on the groups page.
Logged

Mansour

  • Coppermine newbie
  • Offline Offline
  • Posts: 2
Re: Secure the upload?
« Reply #2 on: January 19, 2007, 01:04:58 pm »

Hi,

thanks for this response,

I don't want to do it with cpg, I would like to make sure nobody can upload any file on the server using cpg even if the upload allowed for some user.

I mean add password on the folders, or change the folder permissions


Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Secure the upload?
« Reply #3 on: January 20, 2007, 11:07:45 am »

CHMOD then if you think that this is the proper method (which it is not). Not related to coppermine, but webserver setup. As suggested, disabling uploads is all that it takes unless you have backdoors on your server.
Logged
Pages: [1]   Go Up
 

Page created in 0.018 seconds with 20 queries.